Random in Security 202349

Covering the recent security news

2 min read - 339 words

Introduction

Random in Security is a summary of the cybersecurity news.

Vulnerabilities

LogoFAIL: Security Implications of Image Parsing During System Boot

The paper discusses the security implications of image parsing during system boot and how it can be exploited by attackers to gain unauthorized access to the system.4 The authors demonstrate several attacks that can be launched using image parsing, including logo manipulation, firmware vulnerabilities, and bootloader attacks.

CVE-2022-1471 - Remote Code execution in SnakeYAML

This vulnerability is rated with a CVSSv3 9.8 and was released in 2022 and has reemerged in the Atlassian December 2023: Security Advisories Overview. Apache Submarine was also affected and the ticket SUBMARINE-1371 even contains an curl request to trigger the vulnerability.

Interesting Reads

Inside Job: How a Hacker Helped Cocaine Traffickers Infiltrate Europe’s Biggest Ports - OCCRP

The article discusses how criminal groups have found new ways to smuggle drugs into Europe through commercial ports, using digitalization and automation to their advantage. A Dutch hacker named Davy de Valk was hired by drug traffickers to infiltrate the IT systems of major ports in Europe, providing intel on how to move drugs undetected. Initial access vector was via a USB stick for a port employee, who would insert the stick to infect a computer. The article provide a detailled chronology of the hack. De Valk was eventually caught and sentenced to 10 years in prison.

CyberCrime & Doing Time: China continues Pig-Butchering Crack-down

The article highlights the efforts of the Yiyuan County Police in Shandong Province, who have been successful in tracking down and arresting key members of a fraud syndicate. The task force has been able to seize large amounts of money and assets from the criminals, and has also led to the arrest of key leaders of the gang. One relevant reference in the article is @CyberScamWatch as well as @johnwSEAP

Tools

changedetection.io

Web Site Change Detection, Restock monitoring and notifications.

twistrs

A domain name permutation and enumeration library powered by Rust.

Some additional details are available in this thread.